{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T17:04:40Z","timestamp":1778000680827,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":66,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100006374","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2339537"],"award-info":[{"award-number":["CNS-2339537"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690357","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"2711-2725","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Understanding Legal Professionals' Practices and Expectations in Data Breach Incident Reporting"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-6438-9557","authenticated-orcid":false,"given":"Ece","family":"Gumusel","sequence":"first","affiliation":[{"name":"Indiana University Bloomington, Bloomington, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-7945-464X","authenticated-orcid":false,"given":"Yue","family":"Xiao","sequence":"additional","affiliation":[{"name":"Indiana University Bloomington &amp; IBM Research, Bloomington, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7857-2936","authenticated-orcid":false,"given":"Yue","family":"Qin","sequence":"additional","affiliation":[{"name":"Indiana University Bloomington, Bloomington, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-2110-0532","authenticated-orcid":false,"given":"Jiaxin","family":"Qin","sequence":"additional","affiliation":[{"name":"China University of Political Science and Law, Beijing, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7555-1673","authenticated-orcid":false,"given":"Xiaojing","family":"Liao","sequence":"additional","affiliation":[{"name":"Indiana University Bloomington, Bloomington, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2019 Capital One Cyber Incident | What Happened | Capital One. https:\/\/www.capitalone.com\/digital\/facts2019\/."},{"key":"e_1_3_2_1_2_1","unstructured":"Cisa cybersecurity alerts & advisories."},{"key":"e_1_3_2_1_3_1","unstructured":"Codebook. https:\/\/docs.google.com\/spreadsheets\/d\/1UiZJGsbFU0GPUvPkjWtjMGK4rxGeaE92\/edit?usp=drive_link."},{"key":"e_1_3_2_1_4_1","unstructured":"Contact Survey Questions. https:\/\/docs.google.com\/document\/d\/126W6CDR4bkECknHC7Nvg8Pu8QdyswEFyc8nGf2pnxxY\/edit?usp=drive_link."},{"key":"e_1_3_2_1_5_1","unstructured":"GDPR Enforcement Tracker - list of GDPR fines. https:\/\/www.enforcementtracker.com."},{"key":"e_1_3_2_1_6_1","unstructured":"Informed Consent Statement. https:\/\/docs.google.com\/document\/d\/17Ze5ryrX1WcljYyRArz_XBDVTijFvmXVo9oudfOurFk\/edit?usp=drive_link."},{"key":"e_1_3_2_1_7_1","unstructured":"Inter-annotator Agreement. https:\/\/docs.google.com\/document\/d\/1C-BbIZo6vyjgybfoU5tka1LtXnnGAuuDfeOqdXrefdk\/edit?usp=drive_link."},{"key":"e_1_3_2_1_8_1","unstructured":"Interview Script. https:\/\/docs.google.com\/document\/d\/1Tdpl4Wg9jhVgEY_OEgjneeyAJ1CJha6arOETgjjPUq4\/edit?usp=sharing."},{"key":"e_1_3_2_1_9_1","unstructured":"National Initiative for Cybersecurity Careers and Studies Workforce Framework for Cybersecurity (NICE Framework). https:\/\/niccs.cisa.gov\/workforce-development\/nice-framework."},{"key":"e_1_3_2_1_10_1","unstructured":"NIST. https:\/\/nvlpubs.nist.gov\/nistpubs\/specialpublications\/nist.sp.800--61r2.pdf."},{"key":"e_1_3_2_1_11_1","unstructured":"Participants Demographics. https:\/\/docs.google.com\/document\/d\/1ulB7LnEWnlG9LwoGhw69GxWFTlGtbdfB\/edit?usp=drive_link."},{"key":"e_1_3_2_1_12_1","unstructured":"Post Interview Questions. https:\/\/docs.google.com\/document\/d\/11xe0FPQ_13NmGoLDP8KtjTqueeP1pXv8n6dFgdZVcko\/edit?usp=drive_link."},{"key":"e_1_3_2_1_13_1","unstructured":"Recruitment Advertisements. https:\/\/docs.google.com\/document\/d\/16xRREevCrLrhTpLTGciLUXrHmMiGeze4L6oc1JF3tVE\/edit?usp=drive_link."},{"key":"e_1_3_2_1_14_1","unstructured":"Screening Interview Questions. https:\/\/docs.google.com\/document\/d\/1c7uTArOVX12V0r7cuYXExOFUIeQDs_3lf5MvbSjijoo\/edit?usp=drive_link."},{"key":"e_1_3_2_1_15_1","unstructured":"Survey Questions. https:\/\/docs.google.com\/document\/d\/1n8f1p1atPW04HqLWhsra-7VOm0yYGDMKA6tRtYriN24\/edit?usp=sharing."},{"key":"e_1_3_2_1_16_1","volume-title":"The New York Times, 2018","author":"Analytica Cambridge","year":"2018","unstructured":"Cambridge Analytica and Facebook: The Scandal and the Fallout So Far. The New York Times, 2018. https:\/\/www.nytimes.com\/2018\/04\/04\/us\/politics\/cambridge-analytica-scandal-fallout.html."},{"key":"e_1_3_2_1_17_1","volume-title":"Jul","author":"Breach Equifax Data","year":"2019","unstructured":"Equifax Data Breach Settlement 2019. Federal Trade Commission, Jul 2019. https:\/\/www.ftc.gov\/enforcement\/refunds\/equifax-data-breach-settlement."},{"key":"e_1_3_2_1_18_1","unstructured":"App privacy details on the App Store 2021. https:\/\/developer.apple.com\/app-store\/app-privacy-details\/."},{"key":"e_1_3_2_1_19_1","volume-title":"Improving transparency and empowering users","author":"Apple Data","year":"2021","unstructured":"Data privacy day at Apple: Improving transparency and empowering users, 2021. https:\/\/www.apple.com\/newsroom\/2021\/01\/data-privacy-day-at-apple-improving-transparency-and-empowering-users\/."},{"key":"e_1_3_2_1_20_1","volume-title":"Congress on Privacy and Security. Federal Trade Commission","author":"FTC","year":"2021","unstructured":"FTC Report to Congress on Privacy and Security. Federal Trade Commission, Oct 2021. https:\/\/www.ftc.gov\/reports\/ftc-report-congress-privacy-security."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00779-021-01544-1"},{"issue":"1","key":"e_1_3_2_1_22_1","first-page":"1","article-title":"What a hybrid legal-technical analysis teaches us about privacy regulation: The case of singling out","volume":"27","author":"Altman Micah","year":"2021","unstructured":"Micah Altman, Aloni Cohen, Kobbi Nissim, and Alexandra Wood. What a hybrid legal-technical analysis teaches us about privacy regulation: The case of singling out. Boston University Journal of Science and Technology Law, 27(1):1--63, 2021.","journal-title":"Boston University Journal of Science and Technology Law"},{"key":"e_1_3_2_1_23_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security'20)","author":"Andow Benjami","year":"2020","unstructured":"Benjami Andow, Samin Yaseer Mahmud, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Serge Egelman. Actions speak louder than words: Entity-sensitive privacy policy and data flow analysis with policheck. In Proceedings of the 29th USENIX Security Symposium (USENIX Security'20), 2020."},{"key":"e_1_3_2_1_24_1","first-page":"585","volume-title":"USENIX Security Symposium","author":"Andow Benjamin","year":"2019","unstructured":"Benjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Tao Xie. Policylint: Investigating internal privacy policy contradictions on google play. In USENIX Security Symposium, pages 585--602, 2019."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1080\/01972243.2019.1583296"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/RE54965.2022.00016"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/RE.2013.6636701"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484536"},{"issue":"6","key":"e_1_3_2_1_29_1","first-page":"2011","volume":"26","author":"Campbell Karen A.","year":"2021","unstructured":"Karen A. Campbell, Elizabeth Orr, Pamela Durepos, Linda Nguyen, Lin Li, Carly Whitmore, Paige Gehrke, Leslie Graham, and Susan M. Jack. Reflexive Thematic Analysis for Applied Qualitative Health Research. The Qualitative Report, 26(6):2011--2028, 06 2021.","journal-title":"Jack. Reflexive Thematic Analysis for Applied Qualitative Health Research. The Qualitative Report"},{"key":"e_1_3_2_1_30_1","volume-title":"Inductive Coding, page 91--106","author":"Chandra Yanto","year":"2019","unstructured":"Yanto Chandra and Liang Shang. Inductive Coding, page 91--106. Springer Nature Singapore, Singapore, 2019."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00054"},{"issue":"6","key":"e_1_3_2_1_32_1","first-page":"897","article-title":"In the Beginning - An Early History of the Privacy Profession Symposium","volume":"74","author":"Clearwater Andrew","year":"2013","unstructured":"Andrew Clearwater and J. Trevor Hughes. In the Beginning - An Early History of the Privacy Profession Symposium: The Second Wave of Global Privacy Protection. Ohio State Law Journal, 74(6):897--922, 2013.","journal-title":"The Second Wave of Global Privacy Protection. Ohio State Law Journal"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1037\/h0026256"},{"key":"e_1_3_2_1_34_1","first-page":"33","volume-title":"Christiaan Hillen. A Critical Analysis of Privacy Design Strategies. In 2016 IEEE Security and Privacy Workshops (SPW)","author":"Colesky Michael","year":"2016","unstructured":"Michael Colesky, Jaap-Henk Hoepman, and Christiaan Hillen. A Critical Analysis of Privacy Design Strategies. In 2016 IEEE Security and Privacy Workshops (SPW), pages 33--40, 2016."},{"key":"e_1_3_2_1_35_1","volume-title":"The Commission","author":"United States.","year":"1998","unstructured":"United States. Federal Trade Commission. Privacy online: a report to Congress. The Commission, 1998."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23082"},{"key":"e_1_3_2_1_37_1","volume-title":"Official Journal of the European Union","author":"General Data Protection EU.","year":"2016","unstructured":"EU. General Data Protection Regulation (EU) 2016\/679. Official Journal of the European Union, 2016."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2016.37"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3544902.3546234"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0119"},{"key":"e_1_3_2_1_41_1","volume-title":"Qualitative Data Analysis with NVivo","author":"Kristi Jackson Patricia Bazeley","year":"1981","unstructured":"Patricia Bazeley Kristi Jackson. Qualitative Data Analysis with NVivo. SAGE Publications Inc, 1981."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/RE.2014.6912250"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/RE.2013.6636702"},{"key":"e_1_3_2_1_44_1","first-page":"993","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Nan Yuhong","year":"2015","unstructured":"Yuhong Nan, Min Yang, Zhemin Yang, Shunfan Zhou, Guofei Gu, and XiaoFeng Wang. Uipicker: User-input privacy identification in mobile applications. In 24th USENIX Security Symposium (USENIX Security 15), pages 993--1008, 2015."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23092"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2015.22"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2015.22"},{"key":"e_1_3_2_1_48_1","unstructured":"CHAPTER I GENERAL PROVISIONS. Directive 95\/46\/ec of the European parliament and of the council on the protection of individuals with regard to the processing of personal data and on the free movement of such data. Official Journal L 281(23\/11):0031--0050 1995."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2018-0021"},{"key":"e_1_3_2_1_50_1","volume-title":"Europe's enforcement paralysis: ICCL?s 2021 GDPR report","author":"Ryan Johnny","year":"2021","unstructured":"Johnny Ryan. Europe's enforcement paralysis: ICCL?s 2021 GDPR report. Irish Council for Civil Liberties, Sep 2021. https:\/\/www.iccl.ie\/digital-data\/2021-gdpr-report\/."},{"key":"e_1_3_2_1_51_1","volume-title":"The New York Times","author":"Singer Natasha","year":"2019","unstructured":"Natasha Singer and Kate Conger. Google Is Fined 170 Million for Violating Children's Privacy on YouTube. The New York Times, Sep 2019."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884855"},{"key":"e_1_3_2_1_53_1","volume-title":"Bloomberg Law","author":"Smith Mark","year":"2021","unstructured":"Mark Smith and Jackquelyn Palmer. ANALYSIS: Three Years Later, GDPR Compliance Still a Challenge. Bloomberg Law, 2021. https:\/\/news.bloomberglaw.com\/bloomberg-law-analysis\/analysis-three-years-later-gdpr-compliance-still-a-challenge."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2008.88"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.17"},{"key":"e_1_3_2_1_56_1","first-page":"385","volume-title":"Compliance requirements in large-scale software development: An industrial case study","author":"Usman Muhammad","year":"2020","unstructured":"Muhammad Usman, Michael Felderer, Michael Unterkalmsteiner, Eriks Klotins, Daniel Mendez, and Emil Al\u00e9groth. Compliance requirements in large-scale software development: An industrial case study. In Maurizio Morisio, Marco Torchiano, and Andreas Jedlitschka, editors, Product-Focused Software Process Improvement, page 385--401, Cham, 2020. Springer International Publishing."},{"key":"e_1_3_2_1_57_1","first-page":"4133","volume-title":"USENIX Security Symposium","author":"Wang Jice","year":"2021","unstructured":"Jice Wang, Yue Xiao, Xueqiang Wang, Yuhong Nan, Luyi Xing, Xiaojing Liao, JinWei Dong, Nicolas Serrano, Haoran Lu, XiaoFeng Wang, et al. Understanding malicious cross-library data harvesting on android. In USENIX Security Symposium, pages 4133--4150, 2021."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180196"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.5325\/jinfopoli.11.2021.0063"},{"key":"e_1_3_2_1_60_1","first-page":"2259","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Woods Daniel W","year":"2023","unstructured":"Daniel W Woods, Rainer B\u00f6hme, Josephine Wolff, and Daniel Schwarcz. Lessons lost: Incident response in the age of cyber insurance and breach attorneys. In 32nd USENIX Security Symposium (USENIX Security 23), pages 2259--2273, 2023."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2021.3096742"},{"key":"e_1_3_2_1_62_1","volume-title":"Lalaine: Measuring and characterizing non-compliance of apple privacy labels at scale. arXiv preprint arXiv:2206.06274","author":"Xiao Yue","year":"2022","unstructured":"Yue Xiao, Zhengyi Li, Yue Qin, Jiale Guan, Xiaolong Bai, Xiaojing Liao, and Luyi Xing. Lalaine: Measuring and characterizing non-compliance of apple privacy labels at scale. arXiv preprint arXiv:2206.06274, 2022."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2016.55"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0037"},{"key":"e_1_3_2_1_65_1","volume-title":"2016 AAAI Fall Symposium Series","author":"Zimmeck Sebastian","year":"2016","unstructured":"Sebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar, Bin Liu, Florian Schaub, Shomir Wilson, Norman Sadeh, Steven Bellovin, and Joel Reidenberg. Automated analysis of privacy requirements for mobile apps. In 2016 AAAI Fall Symposium Series, 2016."},{"key":"e_1_3_2_1_66_1","volume-title":"Automation potentials in privacy engineering. 05","author":"Zimmermann Christian","year":"2020","unstructured":"Christian Zimmermann. Automation potentials in privacy engineering. 05 2020."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690357","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690357","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T06:07:08Z","timestamp":1755842828000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690357"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":66,"alternative-id":["10.1145\/3658644.3690357","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690357","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}